Cross-Site Scripting Vulnerability in WorklogPRO for Jira Data Center
CVE-2025-67824
6.1MEDIUM
Key Information:
- Vendor
Atlassian
- Vendor
- CVE Published:
- 20 January 2026
What is CVE-2025-67824?
The WorklogPRO - Jira Timesheets plugin for Jira Data Center versions prior to 4.24.1-jira9, 4.24.1-jira10, and 4.24.1-jira11 contains a vulnerability that enables attackers to inject arbitrary HTML or JavaScript code. This occurs when a crafted payload is inserted into the name of a filter, which is subsequently executed in the user's browser as they create a timesheet using the affected filter in the custom timesheet dialog. The vulnerability results from improper sanitization of the filter name during the execution process, allowing for potential exploitation.